European alternatives to Cloudflare Zero Trust and Zscaler: what to look at
Why EU firms look past US ZTNA providers (CLOUD Act, FISA 702, NIS2), what to check in a vendor, and a verified look at NetBird, GoodAccess, Enclave and more.
Zero trust network access (ZTNA) sits in the path of every login to your internal apps. The service sees who connected, from which device and IP address, to which system and when. Two of the best-known services, Cloudflare Zero Trust and Zscaler Private Access, come from American companies. This article explains why that matters to some buyers and which European options exist today. Prices and company details were checked on each vendor's own site on 29 September 2026.
Why European companies look for an EU alternative
The US CLOUD Act
The CLOUD Act was signed into US law in March 2018. Its core provision, 18 U.S.C. § 2713, requires a provider of electronic communication or remote computing services to disclose data in its "possession, custody, or control" whether that data is stored inside or outside the United States. For a provider under US jurisdiction, an EU data centre changes where the data is stored, and the disclosure obligation still applies to it.
That can put a provider between two legal systems. In their joint assessment of July 2019, the European Data Protection Board and the European Data Protection Supervisor concluded that providers subject to EU law cannot base a disclosure of personal data to the US on a CLOUD Act request alone, without an international agreement or another legal basis under the GDPR.
FISA section 702 and the Data Privacy Framework
Section 702 of the Foreign Intelligence Surveillance Act allows US intelligence agencies, with approval of the surveillance court, to target non-US persons located outside the United States, with service providers required to hand over the communications. In Schrems II (16 July 2020), the Court of Justice found that section 702 does not indicate limits on that power or guarantees for non-US persons, and it declared the EU-US Privacy Shield invalid.
The European Commission adopted a new adequacy decision, the EU-US Data Privacy Framework, on 10 July 2023. The General Court dismissed a challenge to it on 3 September 2025 (case T-553/23, Latombe v Commission). The applicant appealed on 31 October 2025, and the appeal (C-703/25 P) is pending before the Court of Justice. On the US side, the statutory authority for section 702 expired in June 2026 after Congress did not renew it, and had not been renewed at the time of writing, but the Brennan Center points out that surveillance under existing certifications can continue until March 2027.
The framework is valid law today. The Court of Justice struck down the two earlier US frameworks, Safe Harbour and Privacy Shield, and the current one is under appeal. Some companies accept that risk. Others prefer an access layer whose operator sits entirely under EU law.
NIS2 supplier risk
For companies in scope of NIS2, supplier choice is part of the security duty. Article 21(2)(d) of Directive (EU) 2022/2555 lists supply chain security, "including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers", among the minimum measures. Article 21(3) asks entities to take into account the vulnerabilities specific to each direct supplier and the quality of its cybersecurity practices. NIS2 does not ban non-EU providers. A ZTNA vendor is a direct supplier with a privileged position in your network, so where it is based and where it hosts your data belong in that assessment.
What to look at when you compare ZTNA vendors
- Where the company is incorporated and who owns it. A European subsidiary of a US parent is a different case from a company with no US parent.
- Where the relay or edge runs and where the control plane runs. They are often in different places, and the control plane holds your policies and user directory.
- Where connection and audit logs are stored and for how long. ZTNA logs are personal data: user identifiers, IP addresses and device details.
- Whether you can self-host the control plane, the relays or both, and what you lose if you do.
- Whether the code is open source, and under which licence, which affects how you audit it and how you leave.
- Which identity providers it supports (Microsoft Entra ID, Google Workspace, Okta, generic OIDC) and whether it syncs users and groups through SCIM.
- Per-application access or network access. A mesh or network-level product gives a device a route to a subnet. An identity-aware proxy grants access to one application at a time.
- Device posture checks, and whether they come in the base plan or a higher tier.
- The pricing unit: per user, per device or per gateway, and any minimum seat count.
- SME fit: whether a two-person IT team can run it without a partner, and whether a local partner exists if you want one.
European options, and some that are not
The table lists European ZTNA vendors plus two open-source options that are not European: NetFoundry, the company behind OpenZiti, is American, and Headscale is a community project. Prices are list prices from each vendor's pricing page on 29 September 2026, excluding VAT.
| Vendor | Company and country | Hosting | What it does | Published list price |
|---|---|---|---|---|
| NetBird | NetBird GmbH, Berlin, Germany | Managed cloud or self-hosted; open source | WireGuard mesh with SSO, MFA, access policies, private DNS; posture checks on Business | Free up to 5 users; Team EUR 6 and Business EUR 12 per active user per month; Enterprise custom |
| GoodAccess | GoodAccess s.r.o., Ústí nad Labem, Czechia | Managed cloud gateways; no self-hosted edition listed | Cloud gateways for private access, SSO, device posture check, DNS filtering | Essential USD 7 (annual) or USD 9 (monthly), Premium USD 11 or USD 14, per user per month; 5-user minimum |
| Enclave | Enclave Networks Ltd, Newport, Wales, UK | SaaS; no self-hosting option listed | Policy-driven overlay between devices and services, built for MSPs | USD 8 per enrolled system per month, USD 7.33 on annual billing |
| Defguard | Defguard sp. z o.o., Szczecin, Poland | Self-hosted; open source | WireGuard VPN with connection-level MFA, SSO, firewall rules, device posture | Open source free; Business free up to 10 users and 1 location, larger setups priced by calculator; Enterprise custom |
| OpenZiti / NetFoundry | NetFoundry, Inc., Charlotte, North Carolina, US | OpenZiti self-hosted; NetFoundry managed SaaS or self-hosted | Identity-based overlay with SDKs to embed zero trust in applications | Not published |
| Headscale | Community open-source project, no company | Self-hosted only | Open-source replacement for the Tailscale control server | Free (BSD-3-Clause) |
NetBird
NetBird GmbH is registered in Berlin. Its client code is under the BSD-3-Clause licence, while the management, signal and relay components are under AGPLv3, so the whole stack can be self-hosted. The managed cloud includes geo-distributed relays, according to its documentation. That page does not name the country where the cloud control plane runs, so ask. NetBird is a network-level mesh with an agent on each device. It suits teams that want a VPN replacement with an open-source exit and per-user pricing in euros.
GoodAccess
GoodAccess s.r.o. is a Czech company. Its privacy terms say that by default it and its service provider process personal data only within the EU. It is delivered as a managed service with cloud gateways and connectors, integrates with Entra ID, Okta, Google Workspace and JumpCloud, and prices in US dollars. It fits SMEs that want a hosted service and have no appetite for running infrastructure.
Enclave
Enclave Networks Ltd is registered in Wales. The UK is outside the EU, but the Commission renewed its GDPR adequacy decision for the UK on 19 December 2025, valid until 27 December 2031. Enclave is SaaS, priced per enrolled system, and aimed at managed service providers with a multi-tenant partner portal.
Defguard
Defguard is a Polish company based in Szczecin. The product is self-hosted and open source, and it puts multi-factor authentication at the WireGuard connection itself. Its Business plan is free for up to 10 users and one location. It suits teams that want full control and can operate the servers.
OpenZiti and NetFoundry
OpenZiti is developed and open-sourced by NetFoundry, Inc. under the Apache 2.0 licence. NetFoundry is a US company in Charlotte, North Carolina, and offers a managed SaaS or a self-hosted deployment. A self-hosted OpenZiti network keeps data in your own infrastructure. A NetFoundry managed service puts a US company in the path.
Headscale
Headscale is an open-source, self-hosted implementation of the Tailscale control server. Its README says it is not associated with Tailscale Inc. and that it targets a single network for personal use or a small open-source organisation. For a company, it is an option for a technical team that accepts community support.
Non-European vendors with a similar product
Tailscale describes itself as a Canadian company, and its privacy policy says data is processed in Canada, Germany, the US and the UK. Twingate Inc. is a Delaware corporation. Pomerium, Inc. is a Delaware company based in Oregon; on its Zero plans the data plane is self-hosted. Firezone, Inc. is in San Francisco.
Where Cloudflare Zero Trust and Zscaler still stand out
Cloudflare's Zero Trust plans start with a free tier for up to 50 users with up to 24 hours of log retention, followed by pay-as-you-go at USD 7 per user per month with up to 30 days of logs, and contract pricing above that. None of the managed European services above offers a free tier of that size. Cloudflare also sells a Data Localization Suite as an Enterprise-only paid add-on. Its Customer Metadata Boundary can keep logs in the EU or the US. Cloudflare, Inc. is headquartered in San Francisco.
Zscaler, based in San Jose, California, sells private access as part of a larger platform that includes internet access security, data security and digital experience monitoring. In March 2026 it described a dedicated US and European control plane, regional or on-premises log storage, and customer-hosted Private Service Edges. Its pricing page lists bundles but no prices.
Both are large platforms with their own global networks. If you need a full SASE stack, or a free start for a team under 50 users, they belong on the shortlist. Their regional options control where data is stored, while the parent company remains under US law.
AI agents are becoming part of access control
Staff can now connect AI assistants to internal systems through the Model Context Protocol (MCP). The MCP authorization specification builds on OAuth 2.1 for servers reached over HTTP, which moves agent access into the same identity questions as human access.
Vendors are responding in different ways. Cloudflare's MCP server portals put several MCP servers behind one endpoint under Access policies, though the documentation notes that independent MFA, purpose justification and temporary authentication are not enforced for servers authorised through a portal. NetBird's repository lists an Agent Network in beta for identity-aware access to LLM APIs. NetFoundry markets AI access governance.
Some of these features are still in beta. When you evaluate a vendor, ask:
- Can an agent act with the identity and permissions of the person who runs it, instead of a shared service account?
- Can you allow or block individual MCP tools, per user or group?
- Is every agent action logged against a named person, and where are those logs stored?
- Do human and agent access use one policy, or two products with separate rules?
A short note on Flowplane
Flowplane is building a European zero trust gateway for people and AI agents, run by a Belgian company. It is at the concept stage today and will be announced here when there is something to test.
Sources
- 18 U.S.C. § 2713, Required preservation and disclosure of communications and records (Cornell LII)
- EDPB and EDPS, Initial legal assessment of the impact of the US CLOUD Act (July 2019)
- Court of Justice, Case C-311/18, Schrems II, 16 July 2020
- European Commission, EU-US data transfers
- General Court press release 106/25, Case T-553/23, 3 September 2025
- Case C-703/25 P, appeal brought on 31 October 2025 (Official Journal)
- EFF, Section 702 expiry, 12 June 2026
- Brennan Center, Section 702 surveillance will continue until March 2027, 9 June 2026
- Directive (EU) 2022/2555 (NIS2)
- European Commission, renewal of the UK adequacy decision, 19 December 2025
- NetBird pricing, imprint, self-hosted vs cloud, GitHub repository
- GoodAccess pricing, legal, product overview
- Enclave pricing, product overview, Companies House record 08181759
- Defguard pricing, privacy policy
- OpenZiti repository, NetFoundry OpenZiti deployment options, NetFoundry solutions
- Headscale repository
- Tailscale, Canada's Bill C-22 (26 May 2026), Tailscale privacy policy
- Twingate terms, Pomerium Zero terms, Firezone terms
- Cloudflare plans, Data Localization Suite, Customer Metadata Boundary, Cloudflare privacy policy, MCP server portals
- Zscaler pricing, Zscaler sovereignty press release, 12 March 2026
- Model Context Protocol, Authorization specification (2026-07-28)